Vehicle Control Software Rollback Using Local Version Storage

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing vehicle control device systems struggle to efficiently handle defects in updated software, particularly when communication interruptions occur or when the management server does not have the necessary old software versions for rollback.

Innovation Solution

The system incorporates a second non-volatile memory within the vehicle to store old software versions, enabling rapid rollback to a previous software version without relying on external servers, and includes authentication steps to ensure the integrity and legitimacy of the rollback process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If the system relies on external servers to store old software versions, then the device complexity is reduced, but the rollback speed and reliability deteriorate when communication interruptions occur

Engineering Contradiction:
Improvesystem complexityVSAvoidrollback reliability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The system performs preliminary actions by storing old software versions in advance in a second non-volatile memory within the vehicle before updates are applied. This allows the rollback function to operate independently of external servers, ensuring reliability even when communication interruptions occur. The old software is prepared and stored locally ahead of time, eliminating the need for external retrieval during critical rollback operations.

Inventive Principle:
Principle #10Preliminary action

2Quantity of substance

If the system stores old software in external servers, then the loss of storage space in the vehicle is reduced, but the rollback speed deteriorates due to communication dependencies

Engineering Contradiction:
Improvestorage spaceVSAvoidrollback speed
Core Design Contradiction:
Quantity of substanceVSSpeed

Solution Approach 1:

The system performs preliminary action by storing old software versions in advance in a second non-volatile memory within the vehicle. This local pre-storage enables rapid rollback operations without communication delays, as the software is already available in the vehicle's memory system. The trade-off is acceptable storage space consumption in exchange for significantly improved rollback speed and independence from external communication infrastructure.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If the system allows rollback without authentication, then the ease of operation is improved, but the security and integrity of the rollback process deteriorate

Engineering Contradiction:
Improverollback operation easeVSAvoidrollback integrity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system implements authentication feedback mechanisms before allowing rollback operations. The processor verifies authentication information and confirms the legitimacy of the rollback request before executing the software restoration. This feedback loop ensures that only authorized rollback operations are performed, maintaining security and integrity while still providing a relatively straightforward operation for authenticated users. The authentication step acts as a control feedback that prevents unauthorized modifications.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12430121B2Control device and management method
Publication Date: 2025.09.30 TOYOTA JIDOSHA KK
  • US12430121B2 patent drawing
  • US12430121B2 patent drawing
  • US12430121B2 patent drawing

AI summary

The control device of the vehicle comprises a first non-volatile memory storing software for controlling the vehicle and one or more processors executing the software. The one or more processors determine whether the old software before the update is stored in the second non-volatile memory mounted in the vehicle when the software needs to be returned to the old software before the update, and store the old software from the second non-volatile memory to the first non-volatile memory when the old software is stored in the second non-volatile memory.